The General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") is the European Union's framework for the protection of personal data. It applies to the processing of personal data of individuals in the European Union and European Economic Area, regardless of where the organization processing that data is established. This page explains, pillar by pillar, how TINT TECH S.R.L. complies with the GDPR in operating the Student Housing website and mobile application (together, the "Service"). Where a category-specific detail (such as retention periods or the identity of a specific recipient) is involved, it is set out in the Privacy Policy, which this page cross-references throughout.
The data controller responsible for your personal data is TINT TECH S.R.L. Its registration details are set out in the Legal Notice. For any question about the processing of your personal data, you may contact the Controller at contact@tinttechhub.com.
Article 5 of the GDPR sets out the principles that govern all of our processing of personal data:
We only process your personal data where at least one of the following applies:
Article 9 of the GDPR gives extra protection to special categories of data — such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation. We do not intentionally collect or request any special category data through the Service. Lifestyle preferences you may choose to share for roommate matching (such as smoking habits or quiet hours) are ordinary personal data, not special category data. Please do not include special category data in free-text fields such as your bio or messages.
The Service is intended for university students and other adults. In line with Article 8, we do not knowingly collect personal data from anyone under 16, or such higher age of consent as may apply under the law of your habitual residence. If we learn that an account has been created by a person below the applicable age, the account is deactivated and the associated data deleted, as described in Section XI of the Privacy Policy.
We aim to build data protection into the Service rather than add it afterward. In practice, this means: most profile fields are optional and off by default; database access rules restrict each category of data to the users who need it (for example, only the participants in a conversation can read its messages); precise device location is used transiently for search and is not stored against your profile; and account deletion is designed to remove data across the Service, not just your visible profile.
We use technical and organizational measures appropriate to the risk, including encryption in transit and at rest, hashed passwords never accessible to us in plain text, and database access rules scoped to each category of data. The full description of these measures is set out in Section X of the Privacy Policy.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Article 33. Where a breach is likely to result in a high risk to you, we will also notify you directly without undue delay, as required by Article 34.
Where we use other companies to process personal data on our behalf (processors), we do so under a data-processing agreement that requires them to process data only on our instructions and to apply appropriate security measures, as required by Article 28. Our processors include Google Firebase (infrastructure), Google AdMob (advertising), and our email-delivery and hosting providers.
These providers may process and store personal data outside the European Economic Area, including in the United States. Where this happens, we rely on the transfer safeguards recognized under Chapter V of the GDPR that our providers implement, such as the EU–U.S. Data Privacy Framework or the standard contractual clauses adopted by the European Commission.
Under Article 37, a Data Protection Officer must be appointed only where an organization's core activities involve large-scale systematic monitoring of individuals or large-scale processing of special category data. Given the nature and scale of our processing, TINT TECH S.R.L. is not currently required to appoint a Data Protection Officer. Questions about data protection can be addressed directly to the Controller at contact@tinttechhub.com, and we will reassess this position if our processing activities change.
We are responsible for demonstrating compliance with the principles in Section III. In practice, this includes maintaining a record of our processing activities describing the categories of data, purposes, recipients, and retention periods referenced throughout this page and the Privacy Policy; reviewing our practices as the Service evolves; and requiring our processors to provide sufficient guarantees under Article 28.
As a data subject, you have the following rights, at no cost, unless a request is manifestly unfounded or excessive:
Most rights can be exercised directly:
The complete legal description of our data processing — including categories of data, recipients, retention periods, and international transfers — is set out in the Privacy Policy. Our company registration details are set out in the Legal Notice.